i've found that google plus application have a parameter thats vulnerable to XSS https://plus.google.com/up/start/?sw=1&type=st?p=XSS vuln parameter
http://din.gy./xLSlj http://din.gy./xLSlj
_______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/
